Skip to content

WindowsTechs.com

Collaborate Disseminate

Menu

Primary menu

  • Home

Author Archives: Melab

TPM "Reset" versus "Restart" [closed]

Posted on May 14, 2026 by Melab

TPM specifications say that TPM_NV_WRITE_STCLEAR and TPM_NV_GLOBALLOCK permissions mean an NVRAM slot can be locked until the next "TPM Reset" or the next "TPM Restart". But what is the difference between "Restart&… Continue reading TPM "Reset" versus "Restart" [closed]→

Posted in TPM

Difference between platform and owner passwords in TPM 2.0

Posted on January 9, 2025 by Melab

There is a password for the owner hierarchy and there is a password for the platform hierarchy in the TPM 2.0 specification. What is the difference what can either do that the other cannot?

Continue reading Difference between platform and owner passwords in TPM 2.0→

Posted in TPM

Create a password policy for TPM 2.0

Posted on January 5, 2025 by Melab

For an NVRAM slot, I would like to create a TPM 2.0 policy that uses TPM2_PolicyPassword. I assume that tpm2_policypassword is the tool to use to create such a policy, but the man page doesn’t tell me how to specify the desired password. H… Continue reading Create a password policy for TPM 2.0→

Posted in TPM

What is in a TPM policy?

Posted on November 22, 2024 by Melab

Documentation for the tpm2_nvdefine utility mentions using a policy to control access to NVRAM areas.

-L, –policy=FILE:
Specifies the policy digest file for policy based authorizations.

What do these policies look like? How are they enf… Continue reading What is in a TPM policy?→

Posted in TPM

How do nonce hashes prevent replay attacks on Apple Silicon?

Posted on October 16, 2023 by Melab

Apple Silicon-based Macs have a LocalPolicy file that controls the secure boot process. To prevent replay attacks of the LocalPolicy, hashes of nonces are used. From here:

The lpnh is used for anti-replay of the LocalPolicy. This is an SH… Continue reading How do nonce hashes prevent replay attacks on Apple Silicon?→

Posted in apple, Secure Boot

When can TPM_Start(ST_Clear) be issued to a TPM?

Posted on May 9, 2023 by Melab

TPM 1.2 has an NVRAM permission attribute called TPM_NV_PER_WRITE_STCLEAR. The TPM 1.2 specification describes it as

The value is writable until a write to the specified index with a datasize of 0 is successful. The lock of this attribute… Continue reading When can TPM_Start(ST_Clear) be issued to a TPM?→

Posted in TPM

UEFI secure boot anti-rollback

Posted on June 18, 2020 by Melab

I haven’t seen any seen mechanism by which UEFI can detect the most recent update to a binary from being swapped out for an older binary that was signed with the same key as the up-to-date binary. Google’s vboot is the only PC firmware I k… Continue reading UEFI secure boot anti-rollback→

Posted in replay-detection, uefi

Creating a simple self-signed crlertificate with openssl x509/ca/req

Posted on August 9, 2018 by Melab

All I want to do is create a self-signed certificate that is like this:

It has the serial number of 0.
It lacks both a start date and end date.

If this cannot be done using OpenSSL, then I’d like to have the start date be… Continue reading Creating a simple self-signed crlertificate with openssl x509/ca/req→

Posted in OpenSSL

How are relay attacks thwarted?

Posted on September 13, 2017 by Melab

I just now learned that what I now know to be a relay attack is actually a security problem. This is meant to be a very broad question. How are relay attacks thwarted?

Continue reading How are relay attacks thwarted?→

Posted in authentication, Exploit, Identity, man-in-the-middle

Preventing new NVRAM areas from being defined in a TPM

Posted on June 26, 2017 by Melab

Is there anyway to prevent new NVRAM areas from being defined on a TPM until the next reboot (similar to power-cycle types of protection)? The reason I ask is because firmware could check for NVRAM areas at certain hard-coded… Continue reading Preventing new NVRAM areas from being defined in a TPM→

Posted in TPM

Post navigation

← Older posts

Primary Sidebar Widget Area

Infocon Status

Internet Storm Center Infocon Status

Recent Posts

  • Home Depot and Lowe’s already dropped power tool deals for Memorial Day – I found the best May 14, 2026
  • UK Antitrust Regulator Is Officially Investigating Microsoft Office May 14, 2026
  • AT&T, Verizon, T-Mobile Team Up To Eliminate ‘Dead Zones’ Across US May 14, 2026
  • OpenAI Releases Codex on Mobile in Preview May 14, 2026
  • Chrome is Silently Installing 4GB AI Model on Your Device without Consent. Here’s how to find it and remove it. May 14, 2026

Tag Cloud

Agriculture Alzheimer's Disease Art Audio Automation Bluetooth Building and Construction Campervan Camping Cancer Coronavirus (COVID-19) Cycling Dementia Diabetes DNA Electric Vehicles Food Home House Huawei Indiegogo MIT Mobility Moon New Atlas Audio NVIDIA Off-grid Off-road Pedal-assisted Photography Physics Radio Repair RV Samsung Satellite Sony SpaceX spoofing sustainable design The Immune System Tiny Footprint Training Water Zoom

Archives

  • Facebook
  • Twitter
  • Linkedin
  • Email
Copyright © 2026 WindowsTechs.com. All Rights Reserved.
Theme: Catch Box by Catch Themes
Scroll Up